Trust
What we do with data that isn't ours.
Where your data sits, how long we keep it, what we will sign, and who else touches it.
What we operate.
Lawful basis and recordsA processing register covering every category of personal data we handle on a client's behalf, and the basis on which we handle it.
ResidencyEU or UK data residency on request. Where a client requires it, data does not leave the region it was collected in.
RetentionA retention schedule per system, agreed at design time rather than inherited from whatever the database defaults to.
Subject requestsA documented DSAR workflow: access, rectification, erasure and portability, with a stated turnaround.
Privacy managementISO/IEC 27701 operated as a privacy extension to the information security management system.
Agreements available.
Data Processing AgreementStandard DPA covering processing on your behalf, with Standard Contractual Clauses where a transfer requires them.
Business Associate AgreementAvailable for engagements handling protected health information under HIPAA.
ConfidentialityMutual NDA before any system access, and per-engineer confidentiality terms as a condition of employment.
Sub-processors.
The current list of sub-processors, what each one touches and where it is hosted, is provided on request during evaluation and attached to the DPA. Email [email protected]. We notify customers before adding a sub-processor that would process their data.